North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Level(3) filtering (was Yahoo outage summary)

  • From: Roland Dobbins
  • Date: Mon Jul 09 23:28:55 2007
  • Authentication-results: sj-dkim-3; [email protected]; dkim=pass ( sig from cisco.com/sjdkim3002 verified; );
  • Dkim-signature: v=0.5; a=rsa-sha256; q=dns/txt; l=1543; t=1184038024; x=1184902024; c=relaxed/simple; s=sjdkim3002; h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version; d=cisco.com; [email protected]; z=From:=20Roland=20Dobbins=20<[email protected]> |Subject:=20Re=3A=20Level(3)=20filtering=20(was=20Yahoo=20outage=20summar y) |Sender:=20; bh=pv2vdV35UfCZfbeaAv71hQ1fQPcGkitO7MsA1/pnldM=; b=Kvlgor43K/Y1F6cTVYaZPGGFoQaSPq2HR+Xx+FGEHBdqTtfuzitMZ3MQKj8p2faQMHgBzL4z 8iecEBwsoeldOLSh2fTgRYHHw3icBh5Y8kPlp5c45qUUbEAyDUqxnU/z;



On Jul 9, 2007, at 8:10 PM, Chris L. Morrow wrote:

In the
number of customer conversations I've had about this it's always sort of
surprising that people think it's 'ok' to not have a prefix-list : ( cause,
guess what: "if you don't have one and they don't have one... THEY will
get you eventually"

Many folks seem to think that they'll be OK because 'someone else' will be doing this for them, and so they're protected. They also don't think about the fact that they themselves could accidentally cause a problem for others (and, in some cases, for themselves, by acting as an inadvertent sinkhole). But when it's explained to them that a) if everyone thinks that 'someone else' will do the appropriate filtering, then nobody will do it, and b) that they can end up hosing themselves and also taking a big reputational hit, most people I talk to about this seem to understand.


The problem is that this is largely an ad-hoc, 1:1 type of educational effort, which doesn't scale well. And in many cases, folks seem to find it difficult to go to their management and explain that they must invest the opex to implement and maintain these policies (along with BCP38, iACLs, et. al.); sort of an inversion of "The Emperor's New Clothes", heh.

-----------------------------------------------------------------------
Roland Dobbins <[email protected]> // 408.527.6376 voice

Culture eats strategy for breakfast.

-- Ford Motor Company